HackingSupply Chain (3P Vendor)Customer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
LEM
bd_6103ca441e86a097 · schema v1 · pii pii-v1
Full breach record for LEM →LEM Products Direct LLC notified New Hampshire AG of a third-party breach involving its e-commerce platform provider, CommerceV3. Unauthorized access to cardholder data occurred between Nov 24, 2021 and Dec 14, 2022. CommerceV3 discovered the potential access on May 3, 2023, after forensic investigation. LEM Products Direct LLC notified affected individuals on July 13, 2023.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2a62e25c2be5ad4eMontana State AGfiled 2023-07-13Verified
- bd_7ebe8a22e9e79b42California State AGfiled 2023-07-13Verified
- bd_3ec2e221860bb57eOregon State AGfiled 2023-07-20(7d gap)Verified
- bd_86dac13b5049e9baWashington State AGfiled 2023-07-06(7d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lem-products-direct-20230713.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 13, 2023
- Raw hash
- 5ecab7627f57c72ebc88294099279d069131064fde9fe083b9244a92ad89b82a
Reporting entity
- Name
- LEMnorm: lem
- Domain
- lem.com
Victim entity
- Name
- LEMnorm: lem
- Domain
- lem.com
Incident
- Discovered
- May 3, 2023
- Materiality determined
- —
- Notification sent
- Jul 13, 2023
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via CommerceV3
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.